Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-10536: curl may crash or be misused after reset

CVE-2026-10536 · published 3 months ago
Summary

The curl command‑line tool and its libraries can run into a problem when an application sets up certain HTTP/2 connections, then resets and finally closes them. This can cause the program to access memory that has already been released, potentially leading to a crash or allowing an attacker to take control. Update curl to the latest version to fix the issue.

What to do
  • Update debian rootio-curl to version 7.88.1-10+deb12u15.aikido.13.
  • Update alpine curl to version 8.14.1-r20071.
  • Update alpine rootio-curl to version 8.14.1-r20071.
  • Update bellsoft curl to version 8.21.0-r0.
  • Update alpine curl to version 8.14.1-r20077.
  • Update alpine curl to version 8.14.1-r20073.
  • Update alpine rootio-curl to version 8.14.1-r20073.
  • Update alpine rootio-curl to version 8.14.1-r20077.
  • Update alpine curl to version 8.14.1-r20074.
  • Update alpine rootio-curl to version 8.14.1-r20074.
  • Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update curl to version 8.14.1-r20079.
  • Update rootio-curl to version 8.14.1-r20079.
  • Update curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update debian curl to version 8.21.0~rc2-1.
  • Update curl to version 8.14.1-r30075.
  • Update rootio-curl to version 8.14.1-r30075.
  • Update curl to version 8.14.1-r200710.
  • Update rootio-curl to version 8.14.1-r200710.
  • Update curl to version 8.14.1-r20074.
  • Update rootio-curl to version 8.14.1-r20074.
  • Update curl to version 8.14.1-r30076.
  • Update rootio-curl to version 8.14.1-r30076.
  • Update curl to version 8.14.1-r200711.
  • Update rootio-curl to version 8.14.1-r200711.
  • Update curl to version 7.88.1-10+deb12u15.aikido.16.
  • Update rootio-curl to version 7.88.1-10+deb12u15.aikido.16.
  • Update curl to version 8.14.1-r30077.
  • Update rootio-curl to version 8.14.1-r30077.
  • Update curl to version 8.5.0-r00073.
  • Update rootio-curl to version 8.5.0-r00073.
  • Update curl to version 8.14.1-r20075.
  • Update rootio-curl to version 8.14.1-r20075.
  • Update curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update curl to version 8.14.1-r200712.
  • Update rootio-curl to version 8.14.1-r200712.
  • Update curl to version 8.14.1-r20076.
  • Update rootio-curl to version 8.14.1-r20076.
  • Update curl to version 8.5.0-r00074.
  • Update rootio-curl to version 8.5.0-r00074.
  • Update curl to version 8.14.1-r30079.
  • Update rootio-curl to version 8.14.1-r30079.
  • Update curl to version 8.14.1-2+deb13u5.aikido.21.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.21.
  • Update curl to version 8.22.0-r0.
  • Update curl to version 8.21.0-r0.
  • Update curl to version 8.14.1-2+deb13u5.aikido.22.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.22.
  • Update curl to version 8.14.1-r20077.
  • Update rootio-curl to version 8.14.1-r20077.
  • Update curl to version 7.88.1-10+deb12u15.aikido.17.
  • Update rootio-curl to version 7.88.1-10+deb12u15.aikido.17.
  • Update haxx curl to version 8.21.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– curl curl <= 8.20.0
< 8.14.2
< bfbff7852f050232edd3e5ca5c6bf2021c340f5a
8.20.0
– haxx curl >= 7.88.0, < 8.21.0
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Root:Debian:12 debian rootio-curl < 7.88.1-10+deb12u15.aikido.13
Fix: upgrade to 7.88.1-10+deb12u15.aikido.13
Root:Alpine:3.22 alpine curl < 8.14.1-r20071
< 8.14.1-r20073
< 8.14.1-r20074
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.22 alpine rootio-curl < 8.14.1-r20071
< 8.14.1-r20073
< 8.14.1-r20074
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.21 alpine curl < 8.14.1-r20071
< 8.14.1-r20073
Fix: upgrade to 8.14.1-r20071
Root:Alpine:3.21 alpine rootio-curl < 8.14.1-r20071
< 8.14.1-r20073
Fix: upgrade to 8.14.1-r20071
BellSoft Hardened Containers:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Debian:11 debian curl All versions
Debian:12 debian curl All versions
Debian:13 debian curl All versions
Debian:14 debian curl < 8.21.0~rc2-1
Fix: upgrade to 8.21.0~rc2-1
Alpaquita:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Root:Alpine:3.20 alpine curl < 8.14.1-r20077
Fix: upgrade to 8.14.1-r20077
Root:Alpine:3.20 alpine rootio-curl < 8.14.1-r20077
Fix: upgrade to 8.14.1-r20077
Root:Debian:13 debian rootio-curl < 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
Root:Debian:13 debian curl < 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
Root:Alpine:3.20 – curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
< 8.14.1-r200712
Fix: upgrade to 8.14.1-r20079
Root:Alpine:3.20 – rootio-curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
< 8.14.1-r200712
Fix: upgrade to 8.14.1-r20079
Root:Debian:13 – curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
< 8.14.1-2+deb13u5.aikido.21
< 8.14.1-2+deb13u5.aikido.22
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
Root:Debian:13 – rootio-curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
< 8.14.1-2+deb13u5.aikido.21
< 8.14.1-2+deb13u5.aikido.22
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
Root:Alpine:3.22 – curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
< 8.14.1-r30079
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.22 – rootio-curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
< 8.14.1-r30079
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.21 – curl < 8.14.1-r20074
< 8.14.1-r20075
< 8.14.1-r20076
< 8.14.1-r20077
Fix: upgrade to 8.14.1-r20074
Root:Alpine:3.21 – rootio-curl < 8.14.1-r20074
< 8.14.1-r20075
< 8.14.1-r20076
< 8.14.1-r20077
Fix: upgrade to 8.14.1-r20074
Root:Debian:12 – curl < 7.88.1-10+deb12u15.aikido.16
< 7.88.1-10+deb12u15.aikido.17
Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
Root:Debian:12 – rootio-curl < 7.88.1-10+deb12u15.aikido.16
< 7.88.1-10+deb12u15.aikido.17
Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
Root:Alpine:3.15 – curl < 8.5.0-r00073
< 8.5.0-r00074
Fix: upgrade to 8.5.0-r00073
Root:Alpine:3.15 – rootio-curl < 8.5.0-r00073
< 8.5.0-r00074
Fix: upgrade to 8.5.0-r00073
Alpine:v3.23 – curl >= 7.88.0, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Alpine:v3.24 – curl >= 7.88.0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Original advisory text
CVE-2026-10536 in curl - Patched by Root
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-416Use After Free
Timeline
Published3 Jul 2026
Updated9 Oct 2026
First seen24 Jun 2026
Track software like this
Free during beta